While it is still unofficial it seems that we will finally see the release of new merchant levels as defined under the PCI DSS. The new standard will eliminate the confusion between channels (i.e. current merchant levels 2-4 are based on electronic-channel-transactions, those that occur online, and level 1 was for any channel) by eliminating the differentiation. This means that no matter how a merchant accepts a credit card they will be required to meet the appropriate levels of the standard.
Generally this means we will see PCI DSS be applicable to more merchants. The validation requirements will not change for each level, but that still means that remote auditors will see an increase in validation requiring customers.
I will post a link to the site once it is posted.
James J. DeLuccia